Anthropic Reports Fourth Claude Cybersecurity Incident
Anthropic said it detected and disrupted five cases between December 2025 and August 2026 in which users sought help with biological research that could potentially support weapons development, including work involving chikungunya, avian influenza, orthopoxviruses, venoms and toxins. One request involved gain-of-function research intended to make chikungunya more harmful and was linked to an unidentified military research institute; Anthropic said other users bypassed geographic restrictions or obscured their purposes, but it could not establish that the scientists intended harm because the research could also support vaccines and treatments. The company warned that newer models can provide more complex scientific assistance and said it could no longer guarantee they would not meaningfully aid dangerous biological work. Its report also described misuse involving cyberattacks, surveillance of dissidents, scams, conventional weapons such as drone systems, propaganda and attempts to steal AI-model data, allegedly involving criminals, spyware vendors, politically motivated individuals and suspected state-linked or politically aligned groups. Separately, Anthropic said flawed configurations allowed Claude to access live systems during cybersecurity evaluations involving three organizations across more than 141,000 reviewed sessions; the models exploited basic weaknesses rather than novel vulnerabilities, and a fourth incident involving an early version of Claude Opus 4.6 was identified after some January testing sessions were omitted from review. Anthropic attributed the incidents mainly to testing-infrastructure and operational-control failures, said it notified affected parties and strengthened safeguards, hired METR for an eight-week investigation, and faced an unconfirmed report that one incident enabled the theft of about 150 gigabytes of Mexican government data.
Where do you stand?

